Home/Blog/Ransomware

Ransomware

Ransomware attacks continue to evolve with double-extortion tactics and targeted enterprise campaigns. This section analyzes ransomware groups, attack patterns, and defensive strategies CISOs must understand.

62 articles

Progress Ransomware: ShareFile Storage Zone Controllers Disabled Amid Credible Threat (July 2026)
ransomware

Progress Ransomware: ShareFile Storage Zone Controllers Disabled Amid Credible Threat (July 2026)

Progress has directed ShareFile customers to immediately shut down Storage Zone Controllers following a credible ransomware threat. No unauthorized access or data compromise has been confirmed, but account access has been restricted as a precaution.

Jul 16, 20265 min read
Read More
Langflow Ransomware: JadePuffer LLM-Driven Attack Destroys Alibaba Nacos Configurations (June 2025)
ransomware

Langflow Ransomware: JadePuffer LLM-Driven Attack Destroys Alibaba Nacos Configurations (June 2025)

Langflow suffered a critical ransomware incident when the JadePuffer campaign exploited CVE-2025-3248, leading to the autonomous encryption and deletion of 1342 Alibaba Nacos service configurations. The attack was fully orchestrated by a large language model, compressing multi-stage operations into minutes and leaving no possibility of data recovery.

Jul 15, 20265 min read
Read More
DigitalMint Ransomware: Insider Collusion Amplifies BlackCat Extortion (July 2026)
ransomware

DigitalMint Ransomware: Insider Collusion Amplifies BlackCat Extortion (July 2026)

DigitalMint suffered a critical ransomware incident after an insider leaked confidential negotiation data to BlackCat, resulting in higher extortion demands. The breach also implicated Sygnia Cybersecurity Services and led to $1.2 million in losses.

Jul 14, 20265 min read
Read More
Ryuk Ransomware Attacks: U.S. Organizations Targeted in Coordinated Campaign (April 2020)
ransomware

Ryuk Ransomware Attacks: U.S. Organizations Targeted in Coordinated Campaign (April 2020)

Multiple U.S. organizations, including a Michigan company, an Oregon technology firm, and a Texas school, suffered data encryption and operational disruption after Ryuk ransomware attacks orchestrated by Karen Serobovich Vardanyan. Victims paid over $15 million in Bitcoin ransoms.

Jul 13, 20265 min read
Read More
Citrix NetScaler Ransomware: DragonForce Deployed via CitrixBleed 2 Exploit (Early 2026)
ransomware

Citrix NetScaler Ransomware: DragonForce Deployed via CitrixBleed 2 Exploit (Early 2026)

Multiple organizations worldwide were compromised through Citrix NetScaler appliances, with at least one suffering DragonForce ransomware deployment following privilege escalation via CitrixBleed 2.

Jul 12, 20265 min read
Read More
The Gentlemen Ransomware: Global Manufacturing Disruption and Custom Tooling (June 2026)
ransomware

The Gentlemen Ransomware: Global Manufacturing Disruption and Custom Tooling (June 2026)

The Gentlemen ransomware group compromised over 580 organizations worldwide, including 103 manufacturing firms, using custom malware and zero-day exploits. Their attacks caused widespread operational disruption and leveraged a Ransomware-as-a-Service model.

Jul 11, 20265 min read
Read More
GodDamn Ransomware Attack: PoisonX Driver Used for Defense Evasion (June 2026)
ransomware

GodDamn Ransomware Attack: PoisonX Driver Used for Defense Evasion (June 2026)

A targeted organization suffered a GodDamn ransomware attack in June 2026, with threat actors using the PoisonX driver to disable endpoint defenses and facilitate widespread data encryption.

Jul 10, 20265 min read
Read More
Bandai Channel Ransomware: AI-driven JadePuffer Attack and Mass Subscription Cancellations (June 2024)
ransomware

Bandai Channel Ransomware: AI-driven JadePuffer Attack and Mass Subscription Cancellations (June 2024)

Bandai Channel suffered a critical ransomware attack orchestrated by the autonomous AI JadePuffer, resulting in service disruption and nearly 47,000 anime streaming subscriptions being cancelled. The incident marks a significant escalation in the use of AI for fully automated cyberattacks.

Jul 9, 20265 min read
Read More
Union County Ransomware: $1 Million Paid After 2TB Data Theft (May 2025)
ransomware

Union County Ransomware: $1 Million Paid After 2TB Data Theft (May 2025)

Union County, Ohio suffered a ransomware attack by the Kairos group, resulting in the theft of over 2TB of sensitive data. The county paid $1 million in Bitcoin to prevent public release of information affecting 45,487 individuals.

Jul 8, 20265 min read
Read More
Sysdig Ransomware: First AI-Run Attack Encrypts 1,300+ Records (July 2026)
ransomware

Sysdig Ransomware: First AI-Run Attack Encrypts 1,300+ Records (July 2026)

Sysdig was impacted by JadePuffer, the first AI-driven ransomware attack, which encrypted over 1,300 configuration records and stole credentials. The AI agent autonomously exploited vulnerabilities, raising new concerns about attack scalability.

Jul 7, 20265 min read
Read More
Qilin Ransomware: Market Dominance Amid Cybercrime Consolidation (June 2024)
ransomware

Qilin Ransomware: Market Dominance Amid Cybercrime Consolidation (June 2024)

Qilin, a ransomware-as-a-service operation, has rapidly become the dominant ransomware group, compromising nearly 1,500 organizations over the past year. The group’s mature infrastructure and aggressive tactics have led to significant disruption and increased law enforcement scrutiny.

Jul 6, 20265 min read
Read More
Blackpoint Cyber Ransomware: Avalon Framework Delivers CrownX via Phishing (July 2026)
ransomware

Blackpoint Cyber Ransomware: Avalon Framework Delivers CrownX via Phishing (July 2026)

Blackpoint Cyber was targeted by the Avalon malware framework, which deployed CrownX ransomware via multi-stage phishing. Attackers exfiltrated credentials and cryptocurrency wallets, disrupted recovery, and demanded escalating ransom.

Jul 5, 20265 min read
Read More